PT-2017-18164 · Huawei · B2338-168
Adam Pogorzelski
·
Publicado
2017-11-22
·
Atualizado
2017-12-11
·
CVE-2017-8156
CVSS v2.0
7.2
Alta
| Vetor | AV:L/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
B2338-168 version V100R001C00
Description
The issue affects the outdoor unit of the CPE product, where a lack of authentication on the serial port allows an attacker to access the unit without authentication. This could enable the attacker to take control over the outdoor unit.
Recommendations
For version V100R001C00, consider restricting physical access to the serial port on the circuit board of the outdoor unit to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this issue.
Correção
Missing Authentication
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
B2338-168